Pages

Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Friday, August 27, 2010

Camouflage Viruses

You may not heard about Camouflage viruses. It is becacuse, it has never became a threat thanks to the evolution of advanced antivirus scanners. Camouflage viruses are viruses that are capable of infecting a computer by reporting it as a  harmless application to the antivirus software installed in that computer. In the less sophisticated antivirus softwares, the scanning is performed by checking the files for the virus signatures. In such cases, there is a possibility of non-infected files have codes similar to that of the virus codes (a statistical probability) will be notified to the user as virus infected files - a false alarm. This may frighten the user. To avoid this problem, the antivirus softwares implement a logic to ignore a virus signature and not issue alarm under right circumstance.
Eventhough this logic avoid the chances of false alarm, it has opened a door for the virus creators to attempt to camouflage their viruses so that they included the specific characteristics the antivirus softwares were checking for and thus have the antivirus program ignore that particular virus. Fortunately, camouflage virus never became a serious threat, but the possibility existed.
Today, the antivirus scanners are more advanced that they do much more than simply look for a virus signature string. In order to identify the specific virus varient, they not only check for the virus signature, but also even checksum the virus code to identify it. Due to the provision of these cross checks in the antivirus scanner, it would be very difficult for the virus to camouflage itself and spoof the scanner.

                     Add to Technorati Favorites                 Bookmark and Share

Sality Virus : Know more?

When I noticed that most of the visitors to my blog are searching for the remedies for infection by Sality Virus. I have already put a brief post on Sality virus at creatingcomputervirus.blogspot.com/2010/03/sality-virus-symptoms-and-removal.html. Now I think more information must be provided innorder to satisfy the visitors.  Sality is also known as W32/Kookoo-A [Sophos]. Sality was discovered in 2003 June 4. It affects the Operating Systems - Windows 98, Windows 95, Windows XP, Windows Me, Windows NT, Windows 2000.

It will infect executable files on local, removable and remote shared drives. The virus also creates a peer-to-peer (P2P) botnet and receives URLs of additional files to download. It then attempts to disable security software. When it infected my system, it disabled my antivirus software (BitDefender Free Edition), and antimalware software (MalwareBytes Free Edition). It also prevent the use of the anti rootkit software Rootkit Revealer.
 Some forms of Sality virus is reported to steal the key strokes from the infected machines for malicious purposes.W32.Sality will infect executable files on local, removable and remote shared drives. It replaces the original host code at the entry point of the executable to redirect execution to the polymorphic viral code, which has been encrypted and inserted in the last section of the host file. In addition to infecting local and remotely shared executable files, W32.Sality will purposely search for specific registry subkeys to infect the executable files that run when Windows starts. Thus infected computer is like a country under the rule of the terrorists. All the security will be paralysed leading to complete crack down of the system. Sality will also prevent the installation of the antivirus in to the infected computer.
In 2003 when it was first discovered, W32.Sality was a less complicated file infector, prepending its viral code to a host file and having back door capability and keylogging functionality. As years passed, it became more sophisticated by including additional features that aid worm-like propagation, ensure its survival, and perform maliciously damaging activities. Among these activities is the decentralized peer-to-peer network (P2P) that W32.Sality-infected computers create and populate.
As an entry-point obscuring (EPO) polymorphic file infector, the virus gains control of the host body by overwriting the file with complex and encrypted code instructions. The goal of the complex code is to make analysis more difficult for researchers to see the real purpose and functionality implemented in the code.It spreads by infecting executable files on local, removable and remote shared drives. Infected files will have their original, initial instructions overwritten by complex code instructions with the encrypted viral code body located in the last section of the file.
Downloading and executing other malware or security risks is one of the primary goals of this virus. A compromised host carries with it a list of HTTP URLs that point to resources to be downloaded, decrypted, and executed. These URLs can also point to more URLs. The encryption used is RC4 with static keys embedded in the compromised host.

Technical Details:


 In addition to infecting local and remotely shared executable files, W32.Sality will purposely search for the following registry subkeys to infect the executables associated with that subkey, including those executables that run when Windows starts:

HKEY_CURRENT_USER\Software\Microsoft\Windows\ShellNoRoam
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run

Files Created:
 %System%\drivers\[RANDOM FILE NAME]


Registry Subkeys Created:

HKEY_CURRENT_USER\Software\[USER NAME]914
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WMI_MFC_TPSHOKER_80

HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_IPFILTERDRIVER

Registry entries deleted

HKEY_CURRENT_USER\System\CurrentControlSet\Control\SafeBoot


HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

Registry entries modified (final values given)
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\"[INFECTED FILE]" = "[INFECTED FILE]:*:Enabled:ipsec"


HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Setting\"GlobalUserOffline" = "0"

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA" = "0"

Process Injected:

W32.Sality will not inject into processes that belong to the system, the local service or the network service. However, it does inject complex code instructions into other processes, allowing the code to load external DLLs that are downloaded from remote servers into target processes. This virus uses a named mutex based on the injected process ID (PID) for each injection so that it avoid repeatedly injecting code into the same processes.

Recommendations:


Use a firewall to block all incoming connections from the Internet to services that should not be publicly available. By default, you should deny all incoming connections and only allow services you explicitly want to offer to the outside world.

Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.

Ensure that programs and users of the computer use the lowest level of privileges necessary to complete a task. When prompted for a root or UAC password, ensure that the program asking for administration-level access is a legitimate application.

Disable AutoPlay to prevent the automatic launching of executable files on network and removable drives, and disconnect the drives when not required. If write access is not required, enable read-only mode if the option is available.

Turn off file sharing if not needed. If file sharing is required, use ACLs and password protection to limit access. Disable anonymous access to shared folders. Grant access only to user accounts with strong passwords to folders that must be shared.

Turn off and remove unnecessary services. By default, many operating systems install auxiliary services that are not critical. These services are avenues of attack. If they are removed, threats have less avenues of attack.

If a threat exploits one or more network services, disable, or block access to, those services until a patch is applied.

Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services.

Configure your email server to block or remove email that contains file attachments that are commonly used to spread threats, such as .vbs, .bat, .exe, .pif and .scr files.

Isolate compromised computers quickly to prevent threats from spreading further. Perform a forensic analysis and restore the computers using trusted media.

Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.

If Bluetooth is not required for mobile devices, it should be turned off. If you require its use, ensure that the device's visibility is set to "Hidden" so that it cannot be scanned by other Bluetooth devices. If device pairing must be used, ensure that all devices are set to "Unauthorized", requiring authorization for each connection request. Do not accept applications that are unsigned or sent from unknown sources.


Removal:

Since it is hard to install antivirus software in an infected system, it is better to remove it by scanning the infected computer from another computer with an antivirus software capable of detecting and removing Sality virus. Otherwise you may try manual removal which is not recommended.
 

                      Add to Technorati Favorites             Bookmark and Share

Friday, August 14, 2009


Today we are familiar with the term cyber crimes. Sometime we may be a victim of the cyber crime. Most of the cyber crimes are done through the internet. The increasing number of cyber crime has made it difficult to use the internet even for browsing. Some countries have banned the sites related to pornography. Most of the servers creates the black list which contains the name of the websites that may harm the users if viewed. Now let us look into how to use internet safely.
Install a software firewall in your system. The firewall allows you to know about the applications that access the internet and allows you to block the applications from accessing the internet. See the figure below.


There may be virus or trojan installed in your computer that access the internet without your knowledge. The firewall shows all the applications connected to the internet and allows you to block or terminate the application.

As you know, the world's most safest browser is Mozilla Firefox 3.5. It is very fast also. Hence it is more recommended to use Firefox browser. The fire fox has a add-on named Website Of Trust (WOT) which shows how safe the website we visited is. So I recommend you to install this add-on. The screen shot is given below:



If you are visiting a site related to finance, it would be better if you use private browsing option in fire fox. To enable private browsing go to tools menu -> start private browsing. During private browsing, no data will be stored other than downloaded files and bookmarks.

Try to avoid storing user name and passwords in browser. Also change the password periodically. This will ensure more security to your account. Also don't forget to sign out or log out after viewing the website. Do not click on the links that you are unsure about the content.

Try to avoid visiting porn sites and sites that provides serials or cracks for the sharewares. Download files from the servers you trust. For searching software, it would be better if you search software in filehippo or CNET or other such trusted sites.



Add to Technorati Favorites Bookmark and Share





Wednesday, July 22, 2009

Spyware (Part - 3)

Let us see what are the medium through which a spyware infects computer. A spyware in a computer do not try to infect other computers like virus or worms or trojans. It just collects the user details and send to a particular person or firm via internet. Spywares usually get installed in the computer without the knowledge of the user. The spyware usually comes with a useful software. When the user installs the software without knowing that the software contains spyware, the spyware gets installed in to the computer and sends the details about the user stored in the computer. This is against the privacy in using internet. The manufacturer usually presents the spyware as a useful software. The common categories of the software include themes, games, internet utilities such as download accelerators, web boosters etc. Many Internet users were introduced to spyware in 1999, when a popular freeware game called "Elf Bowling" came bundled with tracking software. The cookie is a well-known mechanism for storing information about an internet user on their own computer. If a website stores information about you in a cookie that you don't know about, the cookie can be considered a form of spyware.
Another way of installing is by using the vulnerabilities in the security software provided to block this spyware. This is by making the user to click on a link that is disguised as a pop up asking any thing that makes the user click on the pop-up. that triggers the installing of the spyware. In a few cases, a worm or virus has delivered a spyware payload. Some attackers used the Spybot worm to install spyware that put pornographic pop-ups on the infected system's screen.By directing traffic to ads set up to channel funds to the spyware authors, they profit personally.



Add to Technorati Favorites Bookmark and Share





Monday, July 20, 2009

How to keep your PC virus free

You may be wondered that is there any way to keep the PC from the virus infection. Here are some tips to keep the PC from the viruses:
For keeping the PC from the computer viruses and other malicious applications we need mainly three softwares:

1. Anti-virus
2. Anti Malware Software
3. Rootkit Remover

Now let us see why we have to use these software. Let us took the case of the anti-virus . As you know anti-virus is used to find and destroy the virus. Knowing this most computer users install anti-virus. But many of the people using the anti-virus are not updating the anti-virus properly. This may put your PC in trouble. The anti-virus has generally two parts: 1. virus signature database and 2. anti-virus engine. Each virus has its own signature as a person has his own signature. The virus signature is nothing but a series of codes that is placed in every file it infect. This code is unique for that particular virus. So by simply comparing the virus signature with the data of a file it is easier to detect the presence of the virus. Since more and more viruses are released in to the cyber space daily, the anti-virus firms discovers the virus signatures of the new virus and put the virus signatures in the internet for the user to download. When we update the anti-virus, these signatures are downloaded in to the database of the anti-virus, and anti-virus gains the capability to detect the new viruses. The anti-virus engine compares the virus signature in the virus signature database with the data of the files. If a match is found, the file will be treated as an infected file and took the measures to prevent further infection and deletion of the virus and the recovery of the original file. It also scans memory for the presence of the virus.

The usage of the anti-virus will not guarantee the protection of the PC from all the malicious software. For that purpose we have to use the anti-malware software. Malware Bytes is one of the most common anti-malware software used internationally. The anti-malware software scan the memory as well as the storage device of the PC for the malicious software. This software can effectively remove almost all the malicious softwares in the PC. But there are some malware application that survive this anti malware software. We can use the rootkit remover software for removing that type of applications. Rootkits are capable of killing and hiding different processes running in the Operating System. Some softwares like demon tools use rootkits, but are not malicious software. Rootkit revealer is a rootkit remover tool used today.
These softwares are not enough to keep your PC from all attacks, if you have an internet connection. You must use a firewall to regulate the internet usage by the applications and to prevent the unwanted packets from entering in to the PC. I prefer Sygate Firewall than the windows firewall since it allows to block the unwanted applications from accessing the internet. But do not use more than one firewall for a PC since the firewalls works on its own set of rules and may clash if more than one firewall is used.
Always use the firefox 3.5 browser for more security. The add-ons must be downloaded if it is marked as recommended. Do not install add-on from the third party whom you do not trust.

Always download the softwares from the trusted sites like filehippo,cnet,brothersoft etc. Try to avoid downloading the softwares from the unfamiliar sites. I believe that these tips will help you to keep your PC clean.




Add to Technorati Favorites Bookmark and Share





Friday, April 17, 2009

Google News Alert Virus

Almost all the internet users trust Google for their services. Now the hackers are exploiting this trust. People who want to be in touch with the latest events they activate the Google News Alert. But recently a new virus emerged by the name Google News Alert.
The virus is sent to the victim in the as email same as that of the Google news alert. When the victim opens the mail there will be an article with a link. If the victim clicks on the link, he will be taken to a website. Then a pop-up will come informing that your system is infected with a virus. For removing the virus you have to download some anti viral softwares. The pop-up contains provision for downloading the anti-viral software. If the user allows the computer to download the anti-viral software will result in the installation of the computer virus in the victim's system.
Due to the increasing number of cyber attack it is hard to keep the computer away from the viruses. However taking prevention will reduce the number of attacks to a great extend. So be careful in using the internet. You will get a detailed idea of the above post from: